keycloak-scim/server_admin/topics/threat/scope.adoc

9 lines
506 B
Text
Raw Normal View History

2016-05-31 22:00:59 +00:00
=== Limiting Scope
By default, each new client application has an unlimited `role scope mappings`. This means that every access token that is created
2016-05-31 22:00:59 +00:00
for that client will contain all the permissions the user has. If the client gets compromised and the access token
is leaked, then each system that the user has permission to access is now also compromised. It is highly suggested
that you limit the roles an access token is assigned by using the <<_role_scope_mappings, Scope menu>> for each client.
2016-05-31 22:00:59 +00:00